hkuds
ICS / OT / IoTunknown
Latest CVEs
The 15 most recently published vulnerabilities affecting hkuds.
- CVE-2026-19246HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery6.3
- CVE-2026-19245HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosure3.3
- CVE-2026-19244HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control4.7
- CVE-2026-61808LightRAG: Missing Authentication for Critical API Functions in Default Configuration9.8
- CVE-2026-19243HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injection6.3
- CVE-2026-61736LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests9.3
- CVE-2026-58173Vibe-Trading < 0.1.10 - Path Traversal via Persistent Memory Type6.5
- CVE-2026-58171Vibe-Trading < 0.1.10 - Path Traversal via Swarm Run Identifier4.2
- CVE-2026-58170Vibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging Live Trading Mandates8.3
- CVE-2026-58169Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS-Rebinding Authentication Bypass and Remote Code Execution7.5
- CVE-2026-58168DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to Non-Admin Users8.8
- CVE-2026-56696OpenHarness - Prompt Injection via /issue and /pr_comments Slash Commands5.4
- CVE-2026-56695OpenHarness - Cross-Session Disclosure via /resume and /summary Commands6.5
- CVE-2026-48716nanobot: Path traversal via unsanitized WhatsApp document fileName enables arbitrary file write8.7
- CVE-2026-12203HKUDS AI-Trader Research Export agents.csv information disclosure5.3